Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,048
Critical983
High3,296
Medium11,512
Reset
Showing 8961-8980 of 16048 records
Threat Entry Updated 2024-10-15

CVE-2024-8915 - Category Icon Plugin

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Category Icon

CVE-2024-8915

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-8760 - Page Builder Gutenberg Blocks Plugin

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of data exfiltration such as admin nonces with limited impact. These nonces could be used to perform CSRF attacks within a limited time window. The presence of other plugins may make additional nonces available, which may pose a risk in plugins that don't perform capability checks to protect AJAX…

PLUGIN Page Builder Gutenberg Blocks

CVE-2024-8760

MEDIUM CVSS 5.3 2024-10-12
Threat Entry Updated 2025-03-12

CVE-2024-9047 - Wordpress File Upload Plugin

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.

PLUGIN Wordpress File Upload

CVE-2024-9047

CRITICAL CVSS 9.8 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9704 - Social Sharing Plugin

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Social Sharing

CVE-2024-9704

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9756 - Order Attachments For Woocommerce Plugin

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

PLUGIN Order Attachments For Woocommerce

CVE-2024-9756

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9824 - Image Gallery Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts and update post titles.

PLUGIN Image Gallery

CVE-2024-9824

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9656 - Mynx Page Builder Plugin

The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN Mynx Page Builder

CVE-2024-9656

MEDIUM CVSS 6.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9670 - 2d Tag Cloud Widget By Sujin Plugin

The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 6.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN 2d Tag Cloud Widget By Sujin

CVE-2024-9670

MEDIUM CVSS 6.1 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9776 - Imagepress Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Imagepress

CVE-2024-9776

MEDIUM CVSS 4.4 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9778 - Imagepress Plugin

The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the 'imagepress_admin_page' function. This makes it possible for unauthenticated attackers to update plugin settings, including redirection URLs, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Imagepress

CVE-2024-9778

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-16

CVE-2024-7489 - Mailchimp Wp Plugin

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form color parameters in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mailchimp Wp

CVE-2024-7489

MEDIUM CVSS 4.4 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9187 - Read More Plugin

The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete read more buttons.

PLUGIN Read More

CVE-2024-9187

MEDIUM CVSS 4.3 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9821 - Bot For Telegram On Woocommerce Plugin

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the Telegram Bot Token, a secret token used to control the bot, which can then be used to log in as any existing user on the site, such as an administrator, if they know the username, due to the Login with Telegram feature.

PLUGIN Bot For Telegram On Woocommerce

CVE-2024-9821

HIGH CVSS 8.8 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9860 - Bridge Core Plugin

The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins.

PLUGIN Bridge Core

CVE-2024-9860

MEDIUM CVSS 6.5 2024-10-12
Threat Entry Updated 2024-10-15

CVE-2024-9592 - Paypal Gift Certificate Plugin

The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Paypal Gift Certificate

CVE-2024-9592

MEDIUM CVSS 6.1 2024-10-12
Threat Entry Updated 2024-11-25

CVE-2024-9707 - Hunk Companion Plugin

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

PLUGIN Hunk Companion

CVE-2024-9707

CRITICAL CVSS 9.8 2024-10-11
Threat Entry Updated 2024-10-15

CVE-2024-9616 - Blockmeister Plugin

The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Blockmeister

CVE-2024-9616

MEDIUM CVSS 6.1 2024-10-11
Threat Entry Updated 2024-10-15

CVE-2024-9611 - Increase Upload File Size Maximum Execution Time Limit Plugin

The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Increase Upload File Size Maximum Execution Time Limit

CVE-2024-9611

MEDIUM CVSS 6.1 2024-10-11
Threat Entry Updated 2024-10-15

CVE-2024-9610 - Language Switcher Plugin

The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.7.13. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Language Switcher

CVE-2024-9610

MEDIUM CVSS 6.1 2024-10-11
Threat Entry Updated 2025-01-29

CVE-2024-9587 - Linkz Ai Plugin

The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_linkz' function in versions up to, and including, 1.1.8. This makes it possible for authenticated attackers with contributor-level privileges or above, to update plugin settings.

PLUGIN Linkz Ai

CVE-2024-9587

MEDIUM CVSS 5.4 2024-10-11
Scroll to top